Legal
Privacy policy
What the app holds about your group and its members, who can see it, and how to have it removed.
1The short version
Horizon Vikoba holds the records a savings group keeps about itself: who its members are, what they have contributed, what they have borrowed and repaid. That is the group’s data, not ours.
- We do not sell it, share it for advertising, or use it to train anything.
- One group’s records are closed to every other group. That is enforced in the database queries, not by convention.
- This marketing site keeps no account of you. It runs Google Analytics to count visits, and nothing else; the contact form passes your message to us and stores nothing here.
- When we look inside a group to help it, the group sees that we did — in its own audit log.
2Who holds the data
Horizon Vikoba operates Horizon Vikoba and is responsible for the personal data described here. Each savings group decides what goes into its own book and who in the group may see it. Write to info@horizonvikoba.com about anything on this page.
3What the portal stores
Your login
- Your name and email address.
- Your password, kept as a one-way hash. We cannot read it, and neither can your officers — a reset replaces it rather than revealing it.
- Sessions, so you stay signed in. Deactivating a member deletes their sessions immediately.
Your membership of a group
- The office you hold, and the date you joined.
- A profile photograph, if your group adds one. Photographs are kept in private storage and served only through the app, behind the same checks as everything else — there is no public link to them.
The group’s book
- Hisa, Jamii, kiingilio and faini contributions, by month.
- Loan requests and their terms, who guaranteed them, which officers approved them and when, repayments, and balances owed.
- The cash book, the interest table, and the year-end share-out.
- An audit trail of acts that matter: approvals, changes to money, role changes, and any occasion on which a platform administrator viewed the group.
Nothing else
The portal does not collect location, contacts, device identifiers, or anything about what you do outside it. What this marketing site does is described in the next section, and it is less than most: no account, no third-party fonts fetched from another server, and a contact form that stores nothing.
4This website
The pages you are reading are a plain website, separate from the portal. Two things happen on it that involve you.
Analytics
We use Google Analytics to see how many people visit, which pages they read and roughly where they are, so we know what to improve. It sets cookies in your browser to tell one visit from the next, and Google processes that data on our behalf under its own terms. It does not receive your name, your email address or anything you type into the contact form. Blocking cookies or scripts for this site stops it entirely and the site keeps working.
The contact form
When you write to us, your name, group, email address and message are sent to our email inbox so that we can reply. They are not stored on this website or in a database; the message exists in our mailbox and yours. Submissions are counted for a short while to stop the form being flooded, and that count holds no part of what you wrote.
5Why we hold it
Because the group needs it to run. A savings group cannot work out a member’s share of the profit without knowing what that member contributed, and cannot lend responsibly without knowing what is already owed.
Beyond that, we use the minimum needed to keep the service working: to authenticate you, to send the emails described below, and to investigate a fault a group has reported.
6Who can see it
- Members of your group. Every member can see the group’s loan book and contributions register — that transparency is the point of a savings group. One member cannot open another’s loan request letter.
- Your officers. The chairperson, accountant and secretary can see and record what their office allows, as set out on the features page.
- Other groups: never. A member or loan belonging to another group is not merely hidden from you — the query does not return it.
- Us. Only to run or repair the service, or when your group asks. To see a group’s screens we impersonate one of that group’s own officers, which shows a banner on every screen for the duration and writes the act into the group’s own audit log.
7Email we send
Horizon Vikoba sends only email that is part of running the group. There is no marketing list and nothing to unsubscribe from.
- About your login — a password reset, a notice that your password changed, a notice that your login was suspended. These come from the platform, because a login spans every group you belong to.
- About a group’s business — a welcome, a loan request, an approval. These come from the group’s own address, so it is clear which group is writing.
Where a group has not configured email, the app sends nothing at all and officers reset passwords by hand.
8Who we rely on
To run the service we use:
- a hosting provider, which runs the servers and the database;
- an object-storage provider, which holds member photographs and any loan documents, in a private bucket;
- an email provider, which delivers the messages described above;
- Google Analytics, for visit counts on this website only, never in the portal.
Each is used only to provide the service, and none of them is permitted to use a group’s data for anything of their own. We will name the current providers on request.
9How long we keep it
A group’s book is kept for as long as the group has an account. Financial records are not deleted piecemeal — a repayment can be removed and the loan reopens, but the audit trail of that change remains, because a book that can be silently rewritten is not a book.
When a group closes its account, its records are deleted within 30 days of the request, other than anything we are required to keep for tax or legal reasons.
10Your rights
You can ask us to:
- tell you what we hold about you, and give you a copy;
- correct something that is wrong;
- delete your personal details;
- stop processing your data while a complaint is looked into.
Some of this has to be done with your group rather than by us: your own contributions and loans form part of the group’s book, and removing them would leave the group’s accounts unable to reconcile. Where that applies we will tell you plainly which parts we can remove and which the group must decide on.
Write to info@horizonvikoba.com. We answer within two working days.
11Security
- Traffic is encrypted in transit.
- Passwords are stored as one-way hashes and are never recoverable.
- Photographs and documents live in private storage and are streamed through the app, so a link to one is useless to somebody without access.
- Permission checks run on the server for every page and every action, never in the interface alone.
No system is perfect. If we find a breach affecting a group’s data we will tell that group, and any regulator we are required to tell, without undue delay.
12Changes to this policy
If we change this policy we will update the date shown beside the contents and, where the change is significant, tell groups before it takes effect.