PRIVACY NOTICE

FOR GENERAL USERS AND CLIENTS

The Macroeconomic and Financial Management Institute of Eastern and Southern Africa (MEFMI) takes your privacy very seriously.

This Privacy Notice is intended to set out your rights and answer any queries you may have about your personal data. If you need more information, please contact privacy@mefmi.org

If you have entered into a contract with MEFMI, the controller of your data will be MEFMI and any additional consent you give us.

Our personal information handling policy and procedures have been developed in line with the requirements of the Cyber and Data Protection Act [Chapter 12:07] and applicable national law, the 1995 European Union Data Protection Directive (Directive 95/46/E) and the General Data Protection Regulation (in force from 25 May 2018) and applicable national law.

1. Information that we collect

We collect and process personal data about you when you interact with us, take part in our capacity-building activities and when we purchase goods and services from you. The personal data that we may process includes:

(a) your name;

(b) your username and password where you access our services online;

(c) your home or work address, email address and/or phone number;

(d) your job title;

(e) your payment and delivery details, including billing and delivery addresses where you make purchases from us;

(f) information related to the browser or device that you use to access our website; internet browser and operating system;

(g) recordings of calls that you make to MEFMI; and/or any other information that you provide; and

(h) your education/qualifications and work experience.

2. How we use this information and the legal basis for this use We process the personal data listed for the following purposes:

(a) as required to establish and fulfil a contract with you, for example, if we enter into an agreement to provide or receive services. This may include verifying your identity, making payments, communicating with you, providing client services and arranging the delivery or other provision of services. We require this information in order to enter into a contract with you and are unable to do so without it;

(b) to comply with applicable law and regulation;

(c) in accordance with our legitimate interests in protecting MEFMI’s legitimate business interests and legal rights, including but not limited to, use in connection with legal claims, compliance, regulatory and investigative purposes (including disclosure of such information in connection with legal process or litigation);

(d) with your express consent to respond to any comments or complaints we may receive from you, and/or in accordance with our legitimate interests including to investigate any complaints received from you or from others, about our website, products or services;

(e) we may use the information that you provide to personalise:

(a) our communications to you;

(b) our website; and

(c) products or services for you, in accordance with our legitimate interests; and to monitor use of our websites and online services.

(f) we may use your information to help us check, improve and protect our products, content, services and websites, both online and offline, in accordance with our legitimate interests;

(g) if you provide a credit or debit card, we may also use third parties (such as POS payment providers) to check the validity of the sort code, account number and card number you submit in order to prevent fraud, in accordance with our legitimate interests and those of third parties;

(h) we may monitor any customer account to prevent, investigate and/or report fraud, terrorism, misrepresentation, security incidents or crime, in accordance with applicable law and our legitimate interests;

(i) in circumstances where you contact us by telephone, social media or video calls, calls may be recorded for quality, training and future reference purposes, in accordance with our legitimate interests;

(j) we may use your information to invite you to take part in market research or surveys; and

(k) to send you direct marketing in relation to relevant products and services. Electronic direct marketing will only be sent where you have given your consent to receive it, or (where this is allowed) you have been given an opportunity to opt-out. You will continue to be able to opt-out of electronic direct marketing at any time by following the instructions in the relevant communication.

3. With whom and where will we share your personal data?

(a) We may share your personal data with our partners and stakeholders to process it for the purposes of capacity building, where we collaborate with said partners and stakeholders including the press;

(b) We may also share your personal data with third parties, such as our professional advisors, auditors, legal and financial advisors and marketing and communications agencies where they have agreed to process your personal data in line with this Privacy Notice;

(c) Market research companies;

(d) Our suppliers, business partners and sub-contractors; and

(e) Search engine and web analytics. Personal data may be shared with government authorities and/or law enforcement officials if required for the purposes above, if mandated by law or if needed for the legal protection of our legitimate interests in compliance with applicable laws. Personal data may also be shared with third party service providers who will process it on behalf of MEFMI for the purposes above. Such third parties include, but are not limited to, providers of website hosting, maintenance, call centre operation and identity checking.

4. How long will we keep your personal data

We will not keep your personal information for any purpose for longer than is necessary and will only retain the personal information that is necessary in relation to the purpose. We are also required to retain certain information as required by law or for as long as is reasonably necessary to meet regulatory requirements, resolve disputes, prevent fraud and abuse, or enforce our terms and conditions.

We will keep your information for the length of any contractual relationship you have with us and after that, for a period of 24 months, unless you are a regular client or services provider, in which event we will keep your information for 5 years in line with our records retention policy.

Where you are a prospective participant in MEFMI activities, and where you have expressly consented to us contacting you, we will only retain your data:

(a) until you unsubscribe from our communications; or

(b) for 12 months from when you last interacted with us or our content.

We will only retain your data for a short time beyond the specified retention period to allow for information to be reviewed and any deletion to take place.

In some instances, laws may require MEFMI to hold certain information for specific periods other than those listed above

5. Where is my data stored?

The personal data that we collect from you is stored on MEFMI’s servers in the MEFMI region, in the United States and on the African continent. It may also be processed and may be transferred to, and stored within the EEA, the United States and Africa. It may also be processed by employees operating within or outside Africa who work for us or for one of our stakeholders and/or suppliers,

6. What are my rights in relation to my personal data?

(a) You have the right to ask us not to process your personal data for marketing purposes. You can exercise your right to prevent such processing by mailing privacy@mefmi.org.

(b) Where you have consented to us using your personal data, you can withdraw that consent at any time.

(c) If the information we hold about you is inaccurate or incomplete, you can notify us and ask us to correct or supplement it.

(d) You also have the right, with some exceptions and qualifications, to ask us to provide a copy of any personal data we hold about you.

(e) Where you have provided your data to us and it is processed by automated means, you may be able to request that we provide it to you in a structured, machine readable format.

(f) If you have a complaint about how we have handled your personal data, you may be able to ask us to restrict how we use your personal data while your complaint is resolved. In some circumstances you can ask us to erase your personal data:

(i) by withdrawing your consent for us to use it;

(ii) if it is no longer necessary for us to use your personal data;

(iii) if you object to the use of your personal data and we don’t have a good reason to continue to use it; or

(iv) if we haven’t handled your personal data in accordance with our obligations.

7. Where can I find more information about MEFMI’s handling of my data?

Should you have any queries regarding this Privacy Notice or about MEFMI’s processing of your personal data or wish to exercise your rights, you can contact MEFMI on this email address: privacy@mefmi.org