Data Protection Policy

1. Introduction

This Data Protection Policy explains how Allios collects, uses, stores, and protects personal and business data when you use our services, including SACCO, lending, clinic, and POS modules.

This document supplements our Privacy Policy and Terms of Service.

2. Scope & Roles

Allios acts as a Data Processor, handling Customer Data on behalf of the Customer (Data Controller).

  • Customer (Controller): Determines how and why data is processed.
  • Allios (Processor): Processes Customer Data according to instructions and legal obligations.

Allios does not claim ownership of your data. Customers retain full ownership and control, while Allios processes data solely to deliver and improve its services.

3. Data We Collect

Account & Identity Data
  • Full name, email, phone number, and company details.
  • KYC identifiers or government IDs where required.
Service-Specific Data
  • Financial: bank info, transactions, credit records.
  • Health: patient records, treatment data.
  • Business: inventory, sales, and employee data.

We also collect device and usage data (IP, browser type, session metadata) for functionality and security analytics.

4. Legal Basis for Processing

  • Contractual necessity: To deliver requested services.
  • Legal obligations: To meet KYC/AML, tax, and compliance requirements.
  • Consent: For optional data uses like marketing or integrations.
  • Legitimate interests: For fraud prevention and system security.

5. Third-Party Integrations

Allios integrates with external providers such as Google Services, MTN MoMo, Airtel Money, and analytics tools. We share only minimal data required for each integration, and users can revoke access at any time through their accounts.

6. Security Measures

  • Encryption (TLS/SSL for data in transit, AES-256 for data at rest).
  • Access control and audit logging.
  • Regular vulnerability and penetration testing.
  • Secure backups and disaster recovery procedures.

If a data breach occurs, we’ll notify affected users and authorities in accordance with applicable laws.

7. Data Retention & Deletion

We retain data only as long as necessary or required by law.

  • Customer data: retained while the account is active.
  • Financial data: retained per statutory accounting periods.
  • Health data: retained as per medical record retention laws.

Upon termination, customers have 30 days to export their data before permanent deletion, as outlined in the Terms of Service.

8. International Transfers

Data may be processed outside your country. We use lawful mechanisms (e.g., Standard Contractual Clauses) to ensure adequate protection for cross-border data transfers.

9. User Rights

  • Access, correction, and deletion of personal data.
  • Right to data portability.
  • Right to object to marketing or automated processing.

To exercise these rights, contact our Data Protection Officer below.

10. Contact & DPO

Data Protection Officer (DPO)
Allios Inc.
123 Privacy Lane, Tech City, 12345
Email: [email protected]

11. Policy Updates

We may revise this policy periodically. The latest version will always be available on this page, and material updates will be communicated via email or in-app notices.

Data Protection Policy

Theme Settings

Choose the color mode for your app.

The perfect color mode for your app.

Choose the font family that fits your app.

Choose the gray shade for your app.

Choose the border radius factor for your app.

Save