Privacy Policy
Effective Date: January 2025 | Last Updated: January 2025
Noetic Labs (PTY) LTD (“Company”, “we”, “us”, or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Morokotso mobile application (“App”).
Please read this Privacy Policy carefully. By using the App, you consent to the practices described herein.
1. WHO WE ARE
1.1 Noetic Labs (PTY) LTD is a company incorporated in Botswana, operating the Morokotso application.
1.2 Contact Details:
Address: Fairgrounds Mall, Stanbic Accelerator, Unit G26, Gaborone, Botswana
Phone: +267 78348649
Email: info@noeticlabs.africa
1.3 For privacy-related enquiries, please contact us at the above details with “Privacy Enquiry” in the subject line.
2. DATA PROTECTION ACT 2024 COMPLIANCE
2.1 This Privacy Policy is designed to comply with the Botswana Data Protection Act 2024 (the “DPA”), which came into full effect in October 2025.
2.2 Your Rights Under the DPA:
- Right of Access: Request a copy of your personal data
- Right to Rectification: Correct inaccurate or incomplete data
- Right to Erasure: Request deletion of your data
- Right to Data Portability: Export your data in a machine-readable format
- Right to Object: Object to processing of your data
- Right to Withdraw Consent: Withdraw consent at any time
2.3 Supervisory Authority: The Information and Data Protection Commission (IDPC) of Botswana is the supervisory authority for data protection matters.
Contact the IDPC:
Information and Data Protection Commission
Plot 50371, Block A, IFSC Building
Gaborone, Botswana
You have the right to lodge a complaint with the IDPC if you believe your data protection rights have been violated.
3. INFORMATION WE COLLECT
3.1 Information You Provide Directly:
(a) Account Registration:
- Full name
- Mobile phone number (Botswana format: +267)
- Password (stored in encrypted form)
(b) Profile Information:
- Profile picture/avatar (auto-generated or uploaded)
- Payment method details (bank account numbers, mobile money numbers, account holder names)
(c) Fund-Related Information:
- Fund names and descriptions you create
- Contribution amounts and records
- Transaction details and references
- Proof of payment documents (images, PDFs)
- Loan/Tab information
- Messages and communications within Funds
(d) Support Communications:
- Any information you provide when contacting us for support
3.2 Information Collected Automatically:
(a) Device Information:
- Device type and model
- Operating system version
- Unique device identifiers
- Mobile network information
(b) Usage Information:
- Features you use and actions you take
- Time, frequency, and duration of activities
- Error logs and crash reports
(c) Location Information:
- We do not collect precise location data
- General location may be inferred from IP address
3.3 Information from Third Parties:
(a) Other Users:
- When someone invites you to a Fund, they may provide your phone number
- Other Fund members may see your name and avatar
(b) Service Providers:
- We receive verification confirmations from Twilio (SMS service)
- We receive authentication data from Firebase (Google)
4. HOW WE USE YOUR INFORMATION
4.1 We use your information for the following purposes:
(a) Service Provision:
- Create and manage your account
- Verify your identity through OTP
- Enable you to create, join, and participate in Funds
- Process and record transactions
- Display your information to other Fund members
- Send notifications about Fund activities
(b) Communication:
- Send OTP codes for authentication
- Notify you of contribution deadlines
- Alert you to Fund updates and activities
- Respond to your enquiries and support requests
- Send service announcements
(c) Service Improvement:
- Analyse usage patterns to improve the App
- Debug and fix technical issues
- Develop new features
(d) Security and Compliance:
- Detect and prevent fraud
- Enforce our Terms of Service
- Comply with legal obligations
- Protect our rights and the rights of others
4.2 Legal Basis for Processing (DPA 2024 Compliance):
- Contractual Necessity: Processing necessary to provide you with the Morokotso service (account management, Fund participation, transaction recording)
- Consent: Processing based on your explicit consent (analytics, marketing communications, push notifications)
- Legitimate Interests: Processing for our legitimate business interests (service improvement, security, fraud prevention) where such interests are not overridden by your rights
- Legal Obligation: Processing necessary to comply with Botswana law (financial record keeping for 7 years, regulatory compliance)
5. HOW WE SHARE YOUR INFORMATION
5.1 With Other Users:
(a) Fund Members can see:
- Your name and avatar
- Your contribution status (paid, pending, overdue)
- Your membership tier
- Your role in the Fund (member or administrator)
(b) Based on Fund settings, members may also see:
- Your total contributions
- Whether you have active loans/tabs
- Your payment history within the Fund
(c) Fund Administrators can additionally see:
- Your proof of payment submissions
- Your full transaction history in the Fund
- Your payment method names (not full account numbers)
5.2 With Service Providers:
We share information with third-party service providers who assist us in operating the App:
(a) Firebase (Google):
- Purpose: Authentication, database, file storage
- Data shared: Account information, Fund data, uploaded files
- Location: Servers in South Africa (africa-south1 region)
(b) Twilio:
- Purpose: SMS verification (OTP)
- Data shared: Mobile phone number
(c) DiceBear:
- Purpose: Avatar generation
- Data shared: User name (for generating initials)
5.3 Legal Disclosures:
We may disclose your information if required to do so by law or in response to:
- Court orders or legal process
- Requests from law enforcement agencies
- Regulatory authorities in Botswana
- To protect our rights, property, or safety
5.4 Business Transfers:
If the Company is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change.
5.5 We Do NOT:
- Sell your personal information to third parties
- Share your information for third-party marketing purposes
- Provide your data to data brokers
6. DATA RETENTION
6.1 Account Data: We retain your account information for as long as your account remains active and for a reasonable period thereafter to:
- Allow you to reactivate your account
- Comply with legal obligations
- Resolve disputes
6.2 Fund Data: Transaction records and Fund data are retained:
- While the Fund is active
- For 7 years after Fund completion or archival (for financial record-keeping)
- As required by Botswana financial regulations
6.3 Communication Records: OTP and verification records are deleted after 30 days.
6.4 Backup Data: Backups are retained for up to 90 days for disaster recovery purposes.
7. DATA SECURITY
7.1 We implement appropriate technical and organisational measures to protect your information, including:
(a) Technical Measures:
- Encryption of passwords using bcrypt hashing
- Secure HTTPS connections for all data transmission
- Firebase security rules restricting data access
- Regular security updates and patches
(b) Organisational Measures:
- Limited staff access to personal data
- Employee confidentiality obligations
- Regular security training
- Incident response procedures
7.2 While we strive to protect your information, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security.
7.3 You are responsible for:
- Keeping your password confidential
- Logging out of shared devices
- Reporting any suspected security breaches immediately
8. YOUR RIGHTS
8.1 You have the following rights regarding your personal information:
- (a) Access: Request a copy of the personal information we hold about you.
- (b) Correction: Request correction of inaccurate or incomplete information.
- (c) Deletion: Request deletion of your personal information, subject to legal retention requirements.
- (d) Portability: Request your data in a commonly used electronic format.
- (e) Objection: Object to certain processing of your information.
- (f) Withdrawal of Consent: Where processing is based on consent, withdraw that consent at any time.
8.2 To exercise these rights, contact us at info@noeticlabs.africa. We will respond within 30 days.
8.3 Limitations: Some rights may be limited where:
- We have a legal obligation to retain data
- The request affects the rights of others
- The information is needed for ongoing legal proceedings
9. DATA TRANSFERS
9.1 Your data is primarily stored on Firebase servers located in South Africa (africa-south1 region).
9.2 Some service providers (Twilio) may process data in other jurisdictions. Where this occurs, we ensure appropriate safeguards are in place.
9.3 By using the App, you consent to the transfer of your data to servers outside Botswana where necessary for service provision.
10. CHILDREN'S PRIVACY
10.1 The App is not intended for use by anyone under the age of 18.
10.2 We do not knowingly collect personal information from children under 18.
10.3 If we become aware that we have collected information from a child under 18, we will delete that information promptly.
10.4 If you believe a child has provided us with personal information, please contact us immediately.
11. COOKIES AND TRACKING
11.1 The App does not use cookies in the traditional sense as it is a mobile application.
11.2 We may use similar technologies for:
- Session management
- Authentication
- Analytics and performance monitoring
11.3 You can control certain tracking through your device settings.
12. THIRD-PARTY LINKS
12.1 The App may contain links to third-party websites or services.
12.2 We are not responsible for the privacy practices of these third parties.
12.3 We encourage you to read the privacy policies of any third-party services you access.
13. PUSH NOTIFICATIONS
13.1 With your consent, we may send push notifications about:
- Contribution reminders and deadlines
- Transaction approvals and updates
- Fund activity notifications
- Important service announcements
13.2 You can manage notification preferences in:
- Your profile settings within the App
- Your device notification settings
14. CHANGES TO THIS POLICY
14.1 We may update this Privacy Policy from time to time.
14.2 We will notify you of material changes by:
- Posting the updated policy in the App
- Sending an SMS notification
- Displaying a notice when you next use the App
14.3 The “Last Updated” date at the top indicates when the policy was last revised.
14.4 Your continued use of the App after changes constitutes acceptance of the updated policy.
15. COMPLAINTS
15.1 If you have concerns about how we handle your personal information, please contact us first at info@noeticlabs.africa.
15.2 We will investigate and respond to your complaint within 30 days.
15.3 If you are not satisfied with our response, you may lodge a complaint with the relevant data protection authority in Botswana.
16. HOW TO EXERCISE YOUR RIGHTS
16.1 In-App Features:
You can exercise most of your data rights directly through the Morokotso app:
- Go to Profile → Data & Privacy to request a data export
- Go to Profile → Data & Privacy to request account deletion
- Go to Profile → App Settings to manage notification and analytics preferences
16.2 Written Requests:
You may also submit a written request to info@noeticlabs.africa with the subject line “Data Rights Request”.
16.3 Response Time:
We will respond to all data rights requests within 30 days as required by the DPA 2024. If we need additional time, we will notify you within the initial 30-day period.
16.4 Verification:
To protect your privacy, we may need to verify your identity before processing your request.
16.5 Account Deletion Process:
When you request account deletion:
- Your request will be processed after a 30-day grace period
- You can cancel the request at any time during this period
- After 30 days, your personal data will be permanently deleted
- Transaction records will be anonymized but retained for legal compliance (7 years as required by Botswana financial regulations)
17. CONTACT US
For questions, concerns, or requests regarding this Privacy Policy or your personal information, please contact:
Noetic Labs (PTY) LTD
Data Protection Enquiries
Fairgrounds Mall, Stanbic Accelerator, Unit G26
Gaborone, Botswana
Phone: +267 78348649
Email: info@noeticlabs.africa
We aim to respond to all enquiries within 30 days.
By using Morokotso, you acknowledge that you have read and understood this Privacy Policy.