Who we are
NBOOG Collective Welfare ("NBOOG", "we") operates this member portal for savings, welfare, loans, attendance, and related committee administration. We act as a data controller for member and officer personal data processed through the portal.
Personal data we process
Depending on your role, we may process:
- Identity and membership data (name, member number, status)
- Contact details (email you provide for notices and recovery)
- Authentication data (secure login credentials; passwords are hashed by the identity provider)
- Financial ledger entries (savings, welfare, loans, penalties, repayments)
- Attendance and fine records
- Guarantor and loan-agreement records
- Audit and security logs (role actions, login rate limits, recovery events)
Purposes and legal bases
We process data to:
- Perform membership and welfare administration (contract / membership rules)
- Keep accurate financial and attendance records for the collective
- Secure the portal (fraud prevention, abuse detection, audit)
- Send operational emails (login invites, password reset, email verification, chair-assisted recovery)
- Comply with applicable law and respond to lawful requests
Under Uganda's Data Protection and Privacy Act, Cap. 97 (DPPA), processing is limited to adequate, relevant, and not excessive data for these purposes. Where consent is required (for example, optional contact email for recovery), we ask you to provide it and you may update or revoke it through Settings or the General Secretary where appropriate.
Processors and cross-border hosting
The portal uses specialised processors under our instructions, including identity and database hosting (Supabase), transactional email (Resend), and application hosting. The primary database and authentication service for this portal are hosted in Frankfurt, Germany (European Union). Other processors may also process limited data outside Uganda to deliver email and the website. We rely on contractual and technical safeguards and disclose this transfer here. The committee maintains a confidential processor / transfer register for Personal Data Protection Office (PDPO) inspection.
Continuing to use the portal after reading this notice includes your informed awareness that membership data is stored in the EU for the purposes above (Uganda DPPA s.19 notice / consent path, alongside safeguards).
Retention
Financial and membership history is retained for the life of the collective's accounting and dispute needs, including after a member is soft-deactivated (records stay; portal login is revoked). Authentication tokens and email verification tokens expire automatically. Security audit rows are retained for accountability.
Your rights
Subject to the DPPA and membership rules, you may request access, correction of inaccurate data, restriction of certain processing, and objection where the Act allows. Ledger integrity may limit erasure of historical transactions; instead we may annotate, correct via controlled workflows, or deactivate access. Contact the General Secretary or designated data protection contact for the collective. You may also complain to the Personal Data Protection Office (PDPO) of Uganda.
Security
We apply role-based access, encrypted transport (HTTPS), database row level security, session timeouts, rate limits on sensitive auth actions, and audit logging. No method of transmission or storage is perfectly secure; report suspected incidents to the Chairperson and Treasurer immediately.
Children
The portal is for adult collective members and officers. It is not directed at children.
Contact
For privacy requests, contact the NBOOG General Secretary through the committee channels you already use for membership affairs, or write via the contact published on nboogcollective.com.