How LoanWise Hub handles your personal data. Last changed 27 August 2026.
LoanWise Hub is the data controller for the information described here, and is responsible to you for it under the Data Protection and Privacy Act 2019. Lending activity is conducted under the Tier 4 Microfinance Institutions and Money Lenders Act 2016 and is supervised by the Uganda Microfinance Regulatory Authority.
We do not read, upload, store, infer from or score any of the following, and the app never asks your handset for permission to reach them:
This is not a setting that can be turned on later. Collecting any of it to pursue a debt is forbidden by the Uganda Microfinance Regulatory Authority's digital lending guidelines (s.9.3), by the Data Protection and Privacy Act 2019, and by Google Play's Personal Loans policy. If we ever ask you for one of these permissions, something has gone wrong and you should refuse it and tell us.
We do not sell your data, we do not share it for anybody else's advertising, and we do not pass your details to a debt collector who is not bound by this notice.
These are the periods the platform actually enforces — the table below is read from the rules the disposal process runs on, not written out separately. A period runs from the point the record is closed, not from the day it was created.
| What | Kept for | Then | Because |
|---|---|---|---|
| Applications, scores, inputs and decision records | seven years | moved to a sealed archive that only a compliance officer can open, and deleted from there | FR-SCR-110; ability to reconstruct any decision on regulatory request |
| Complaints register | seven years | moved to a sealed archive that only a compliance officer can open, and deleted from there | UMRA DLG s.17.2 |
| Consent grants and withdrawals | seven years | moved to a sealed archive that only a compliance officer can open, and deleted from there | Data Protection and Privacy Act 2019; evidence of lawful basis |
| Credit reference bureau enquiries and submissions | seven years | moved to a sealed archive that only a compliance officer can open, and deleted from there | Financial Institutions (Credit Reference Bureau) Regulations 2022 |
| Customer profile | seven years | stripped of everything that identifies you, leaving figures that cannot be traced back to a person | Retained while any financial record subsists, then anonymised |
| Identity document and biometric images | seven years | deleted outright | AML/CFT record keeping; NFR-PRV-020 data minimisation on expiry |
| Identity verification results | seven years | moved to a sealed archive that only a compliance officer can open, and deleted from there | AML/CFT record keeping |
| Key Facts statements and acknowledgements | seven years | moved to a sealed archive that only a compliance officer can open, and deleted from there | FR-PRC-030/040; UMRA DLG s.12.4 |
| Loans, ledger entries, transactions and payment attempts | seven years | moved to a sealed archive that only a compliance officer can open, and deleted from there | NFR-MNT-080; tax and UMRA books-and-records obligations |
| Staff and agent accounts | seven years | moved to a sealed archive that only a compliance officer can open, and deleted from there | Employment and audit obligations |
| Cases, contact attempts, promises and field visits | five years | moved to a sealed archive that only a compliance officer can open, and deleted from there | UMRA DLG s.15 conduct evidence |
| Guarantor particulars | three years | deleted outright | Retained three years after the last loan closes |
| Opt-out and unsubscribe records | three years | kept, because deleting it would mean losing the record that you asked not to be contacted | FR-MKT-140: not less than twelve months; held longer to honour the opt-out |
| Support tickets | three years | moved to a sealed archive that only a compliance officer can open, and deleted from there | Service evidence |
| Raw operator callbacks and third-party payloads | two years | deleted outright | Dispute evidence window |
| Sent and suppressed messages with rendered content | two years | deleted outright | Uganda Communications (Text and Multimedia Messaging) Regulations 2019 |
| Leads and incomplete registration attempts | two years | deleted outright | NFR-PRV-020 data minimisation |
| USSD sessions and channel telemetry | one year | deleted outright | Operational troubleshooting only |
Under the Data Protection and Privacy Act 2019 you may ask for a copy of what we hold, ask us to correct it, ask us to delete it, object to a decision made about you by a machine, or withdraw a consent you gave. We must answer within the statutory period, and we answer free of charge.
Where a request would destroy a record we are legally required to keep, we will tell you which part we cannot delete and why, rather than refusing the whole request or quietly doing less than we said.
Your application is scored. The score uses the information you gave us, your history with us, and bureau data — and nothing taken from your handset. You are entitled to be told the main reasons for a decline, to ask for it to be looked at by a person, and to have that reconsideration recorded.
Complain to us first — every complaint is registered and answered. If you are not satisfied, you may complain to the Personal Data Protection Office, and to the Uganda Microfinance Regulatory Authority about the conduct of the lending itself.
Where this notice describes a retention period, that period is generated from the platform's live configuration at the moment you loaded this page.