Introduction & Regulatory Compliance
Afro Ubuntu TradeNet Ltd ("we", "our", or "us") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, and protect your data under:
- UK General Data Protection Regulation (UK GDPR)
- Data Protection Act 2018
- Data (Use and Access) Act 2025
- PECR & Other applicable data-protection laws
- Local laws may also apply where we operate internationally
This Policy applies to our website, account services, dashboards, APIs, communications, approved WhatsApp workflows and related business services.
Ubuntu Commitment: Our data practices are guided by Ubuntu philosophy of "I am, because we are" - ensuring collective benefit while protecting individual rights.
Data Controller Information
Company Details
- Entity: Afro Ubuntu TradeNet Ltd
- Registration: UK Company House #16594596
- Address: 124 City Road, London, UK, EC1V 2NX
- Email: privacy@afroubuntutrade.co.uk
Data Protection Officer
- Contact: dpo@afroubuntutrade.co.uk
- Response Time: 48 hours
- Languages: English
- We refer to this role as our Privacy Lead; this does not imply that we are legally required to appoint a statutory Data Protection Officer.
Data We Collect
Personal Data
Registration Information
- • Full name and business name
- • Phone number and email address
- • Business location and type
- • Account identifiers and verifications information
- • Government ID (where required)
Business Profile
- • Trading patterns and preferences
- • Product categories and inventory
- • Sales, prices, suppliers, orders, payment status and operational records
- • Financial information (for credit scoring)
- • Financial and risk data: information relevant to affordability, business performance, fraud prevention or risk assessment where a feature requires it
- • Business relationships and networks
Technical & Usage Data
- • Device information and mobile OS
- • WhatsApp message metadata (not content)
- • Platform usage patterns and timestamps
- • Image metadata from uploaded photos
- • Photographs of products, shelves, receipts or documents and information extracted from them
- • Location data: approximate or precise location where enabled, disclosed and lawful.
- • IP address, device/browser information, timestamps, log data, security events, page interactions and cookie identifiers.
Special Category Data
We may process special category data only with explicit consent:
- • Biometric data (voice patterns for fraud prevention)
- • Health data (if selling health-related products)
- • Religious/cultural preferences (for appropriate product recommendations)
- We do not seek special-category or criminal-offence data routinely. We process it only when necessary, lawful and supported by an Article 9 or Article 10 condition and appropriate safeguards.
Where Data Comes From
- • Directly from you or an authorised representative.
- • From your organisation, connected accounts or enabled integrations.
- • Automatically from use of the Services, security logs, cookies and similar technologies.
- • From customers, partners, lenders, FMCGs, NGOs, suppliers or public sources where lawful and relevant.
- • From service providers that help verify identity, prevent fraud, deliver communications or support transactions.
- • When information is obtained indirectly, we provide privacy information within the period required by law unless an exemption applies.
Legal Basis for Processing
Consent (Article 6(1)(a) UK GDPR)
For marketing communications, special category data, and optional features.
You can withdraw consent at any time via our platform or by emailing us.
Contract Performance (Article 6(1)(b))
To provide our trade intelligence services and fulfill our contractual obligations.
Legal Obligation (Article 6(1)(c))
For compliance with financial regulations, anti-money laundering, and tax requirements.
Legitimate Interest (Article 6(1)(f))
For fraud prevention, platform improvement, research that benefits the informal trade community and direct marketing subject to PECR and your right to object.
Balancing Test: We regularly assess that our processing doesn't override your rights and freedoms. Where we rely on legitimate interests, we consider necessity, expected benefits and the effect on people’s rights. You may request information about the relevant assessment. Where we rely on consent, you may withdraw it at any time without affecting earlier lawful processing.
How We Use Your Data
AI-Powered Services
- Computer Vision: Analysing product images for inventory tracking (with explicit consent for each upload)
- Natural Language Processing: Understanding WhatsApp communications in local languages
- Predictive Analytics: Demand forecasting and market trend analysis
- Credit Scoring: Ethical assessment based on trading patterns, not traditional demographics
AI Transparency & Control
- Automated Decision-Making: We inform you when AI makes decisions affecting you
- Human Review: You can request human review of any AI decision
- Explanation Rights: We provide clear explanations of AI recommendations
- Opt-Out: You can opt out of AI processing while still using basic services
- • We use AI and profiling to support functions such as inventory recognition, document extraction, demand forecasting, matching, anomaly detection and risk insights.
- • We aim to provide meaningful information about the main factors, data categories and intended effect of significant automated processing, subject to security, confidentiality and intellectual-property limits.
- • Most Outputs support a human decision and are not intended to make a solely automated decision with legal or similarly significant effects.
- • Where we or a customer make such a decision using solely automated processing, the responsible controller must provide required safeguards, including information about the decision, a route to make representations and challenge it, and access to human intervention.
- • Solely automated significant decisions based on special-category data are subject to stricter legal conditions.
- • You may contact privacy@afroubuntutrade.co.uk to ask whether significant automated decision-making applies to you or to request the applicable safeguards
Important distinction
Who We Share Data With
- • Cloud hosting, database, cybersecurity, analytics, communications, customer-support, identity-verification and professional-service providers acting under contract.
- • Meta/WhatsApp and other integration providers when you use or enable their channels.
- • Customers and authorised users within the relevant organisation.
- • Business partners such as FMCGs, fintechs, lenders, NGOs or development organisations, but only where necessary, lawful and consistent with the relevant service and notices.
- • Regulators, courts, law enforcement, tax authorities or other bodies where required or permitted by law.
- • A buyer, investor or successor in connection with a genuine corporate transaction, subject to appropriate confidentiality and data-protection safeguards.
- • We do not sell identifiable personal information. Aggregated or effectively anonymised information may be shared where individuals are not reasonably identifiable.
Data Sharing & International Transfers
Our Commitment
We never sell your personal data. We only share data in these specific circumstances:
Permitted Sharing
- • Service Providers: Cloud hosting, payment processing (under strict contracts)
- • Financial Partners: For credit scoring and lending (with explicit consent)
- • Research Partners: Anonymised data only for market research
- • Legal Compliance: When required by law or court order
International Transfers
- • Adequacy Decisions: Priority for countries with adequate protection
- • Standard Contractual Clauses: For other transfers with additional safeguards
- • Local Data Residency: Critical data stored in-country where required
- • Transfer Impact Assessments: Regular review of transfer risks
Our main hosting may be in the United Kingdom, but providers, partners or users may process information in other countries. For a restricted transfer from the UK, we use an available legal mechanism such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to EU Standard Contractual Clauses, or another lawful safeguard. Where required, we carry out a transfer risk assessment, referred to in legislation as a data protection test, and consider supplementary technical, contractual and organisational measures. Limited statutory exceptions may be used only where the legal conditions are met. You may ask for more information about relevant safeguards by contacting our Privacy Lead.
Your Data Rights
Access Your Data
Download a copy of all your data within 30 days
Rectification
Correct inaccurate or incomplete data
Erasure ("Right to be Forgotten")
Delete your data (subject to legal retention requirements)
Restrict Processing
Limit how we use your data
Data Portability
Export your data in machine-readable format
Object to Processing
Opt out of certain types of processing i.e. based on legitimate interest and object at any time to direct marketing
How to Exercise Your Rights
Submit Request
Via platform or email
Identity Verification
Secure authentication
Response
Within 30 days (max)
You may also:
Cookies, Analytics & Marketing
- • We use necessary technologies for security, authentication, language preference and core functionality.
- • We seek consent before setting non-essential analytics, advertising or similar technologies unless a statutory exception applies.
- • Google Analytics or similar analytics must not load before the required consent is obtained. Your cookie banner and consent-management platform should enforce this technically.
- • You can change cookie choices through the site’s cookie settings and can unsubscribe from marketing at any time.
- • Business-to-business marketing rules vary by channel and recipient type. We apply PECR and data-protection rules to email, SMS, calls and messaging.
Data Security & Breach Management
Technical Safeguards
- • Encryption: AES-256 at rest, TLS 1.3 in transit
- • Access Controls: Role-based with multi-factor authentication
- • Infrastructure: ISO 27001 certified cloud providers
- • Monitoring: 24/7 security monitoring and incident response
Organis ational Measures
- • Staff Training: Regular data protection training
- • Background Checks: For all personnel with data access
- • Incident Response: 72-hour breach notification process
- • Third-Party Audits: Annual security assessments
We use proportionate technical and organisational measures, including access controls, encryption where appropriate, logging, backups, supplier controls and staff confidentiality. No online service is completely secure. Users must protect credentials and report suspected compromise promptly. We assess personal-data breaches and notify the ICO within the statutory period where required. We notify affected people without undue delay where a breach is likely to create a high risk to their rights and freedoms.
Data Breach Response
If we experience a data breach that poses high risk to your rights and freedoms, we will notify you within 72 hours via email and platform notification, including details of the breach and steps you should take.
Data Retention
Retention Periods
- • Active Accounts: Data retained while account is active plus up to 6 years
- • Financial Records: 6 years (legal requirement)
- • Marketing Data: Until consent is withdrawn
- • Research Data: Anonymised data may be retained indefinitely
- • Backup Systems: Data purged from backups within 90 days of deletion
We regularly review and delete data that is no longer necessary for our legitimate business purposes. You can request early deletion of your data, subject to our legal obligations.
How Long We Keep Information
We retain information only as long as reasonably necessary for the purposes described, including legal, accounting, security and dispute requirements. We use a documented retention schedule rather than promising a single period for all data.
- • Account and core service records: generally for the account term and up to six years afterwards where needed for contracts or legal claims.
- • Financial and tax records: normally six years after the end of the relevant accounting period, or longer where law requires.
- • Security logs: typically up to 24 months unless needed for an investigation.
- • Marketing preferences and suppression records: for as long as needed to respect your choices and demonstrate compliance.
- • Support and communications records: normally up to three years after the matter closes, depending on context.
- • Backups: deleted or overwritten according to secure backup cycles; immediate removal from every backup may not be technically possible.
- • Effectively anonymised information may be retained for research, statistics and service improvement because it is no longer personal data.
Children's Privacy
The Services are intended for business users aged 18 or over and are not directed at children. We do not knowingly collect personal data from children under 16 without parental consent, through a service offered directly to them. If we discover that a child’s information has been provided improperly, we will take appropriate steps, which may include deletion, restriction and contacting the responsible organisation or guardian.
If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately at privacy@afroubuntutrade.co.uk.
Complaints & Regulatory Contact
File a Complaint With Us
- • Email: privacy@afroubuntutrade.co.uk
- • Response Time: 48 hours acknowledgment
- • Resolution: 30 days maximum
- • Escalation: Independent ombudsman available
- Please contact us first at privacy@afroubuntutrade.co.uk. We will acknowledge and investigate complaints in line with applicable law and our internal procedure.
Regulatory Authority
- • UK ICO: Information Commissioner's Office
- • Website: ico.org.uk
- • Phone: 0303 123 1113
- • Right: Lodge complaint without cost
- You may also have a right to complain to a regulator in another country.
Contact & Policy Updates
Questions about your privacy or data? We're here to help.
Policy Updates: We may update this Policy to reflect legal, technical or service changes. We will notify you 30 days in advance of any material changes to this policy. Minor updates will be posted with version numbers and effective dates and provide additional notice where a change materially affects people.
Afro Ubuntu TradeNet Ltd - 124 City Road, London, EC1V 2NX, United Kingdom - Company number: 16594596